Head to head · Cms content · October 2026 research run

Payload vs WordPress

WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation. Both do cms content.

Which one, for what

Payload C

Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.

Ahead on

  • Schema & documentation, 70 against 65

Watch for

49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026

WordPress B

Good for Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.

Ahead on

  • Agent ergonomics, 74 against 64
  • Security & auth, 62 against 57
  • Payments & pricing, 60 against 45
  • Maintenance & community, 83 against 78
  • Transparency & trust, 68 against 62

Also in its favour

  • Runs on your own machine

Watch for

Application Passwords have no scopes or expiry. Each one carries every capability of its user

Score by category

CategoryWeight this runPayloadWordPressEdge
Reliability16%207878even
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27065Payload +5
Agent ergonomics13%16.26474WordPress +10
Security & auth14%17.55762WordPress +5
Payments & pricing10%12.54560WordPress +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87883WordPress +5
Transparency & trust7%8.86268WordPress +6
Negative events≤15-10-5
Total55.2 · C64.8 · B

Facts side by side

FactPayloadWordPress
KindHTTP APIHTTP API
VendorPayload CMS, Inc. (Figma)WordPress.org (open-source project)
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP, stdio
AuthAPI keyAPI key
PricingFreeFree
x402nono
LicenceMIT for the core and the official packages. Enterprise add-ons are sold separately through salesGPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-232026-10-06
Terms last updatedno document linkedno document linked
Privacy policy last updated2024-03-28no date given
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity45k stars, 1.1M npm/wk21k stars

Verdicts

Payload

Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.

WordPress

The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.

Before you call either

Payload

  1. Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
  2. Send REST keys as Authorization: {collection-slug} API-Key {key} and MCP keys as Authorization: Bearer {key}. The two key kinds are separate
  3. To publish, set _status: 'published' in the data. The draft parameter only relaxes validation and chooses where an update is written
  4. Upload files with multipart POST to the upload collection, with other fields as JSON in _payload. No MCP upload tool is documented
  5. Roll back with POST /api/{collection-slug}/versions/:id after listing versions. Versions exist only where the collection config enables them

WordPress

  1. Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them
  2. Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment
  3. Upload a file with POST /wp-json/wp/v2/media first, then set featured_media or reference the returned URL in the post content
  4. To roll back, GET /wp/v2/posts/<id>/revisions/<rev>?context=edit and POST its title and content to the post. There's no restore route
  5. Pass _fields=id,status,link,modified on lists and read X-WP-TotalPages. per_page stops at 100

Questions

Which is better for AI agents, Payload or WordPress?

WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation.

Do Payload and WordPress need an API key?

Both need an API key.

Can an agent call Payload and WordPress without installing anything?

No hosted endpoint is listed for Payload. WordPress runs on your own machine, with no hosted endpoint listed.

Are Payload and WordPress open source?

Yes. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).

Other comparisons with Payload or WordPress

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.